# Logstash filter not working

**URL:** <https://discuss.elastic.co/t/logstash-filter-not-working/157984>\
**Category:** Logstash\
**Created:** [November 23, 2018, 10:07am UTC](https://discuss.elastic.co/t/logstash-filter-not-working/157984 "2018-11-23T10:07:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![DanielE](https://avatars.discourse-cdn.com/v4/letter/d/dfb087/32.png) [@DanielE](https://discuss.elastic.co/u/DanielE)\
**Post date:** [November 23, 2018, 10:07am UTC](https://discuss.elastic.co/t/logstash-filter-not-working/157984/1 "2018-11-23T10:07:30Z")

</div>

Hi gals,

i am using the following filter:

```
filter {
  if [type] == "syslog" {
      if [host] == "X.X.X.X" {
         grok {
          match => { "message" => "<%{POSINT:syslog_pri}>%{SYSLOGTIMESTAMP:syslog_timestamp} %{YEAR} %{DATA:host} %{DATA:syslog_program}: <%{DATA:othernumber}> <%{DATA:pid}> <%{DATA:severity_level}> <%{DATA:hostinfo} %{IP:client}> %{GREEDYDATA:syslog_message}"}
         }
      mutate {
        add_field => {
            system => "Controller"
        }
      }
      } else {
         grok {
           match => { "message" => "<%{POSINT:syslog_pri}>%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:host} %{NUMBER:syslog_pid} %{DATA:syslog_program}: %{GREEDYDATA:syslog_message}"}
         }
      }
      mutate {
         add_field => {
            retention => "medium"
         }
         remove_tag => ["_grokparsefailure_sysloginput"]
      }
  }
}

```

I added if / else clause because the syslogs from this specific IP Looks different, but it does not jump into the if branch of the clause.

Any ideas?

Thank you

---

<div class="post-metadata">

**Author:** ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)\
**Post date:** [November 23, 2018, 10:42am UTC](https://discuss.elastic.co/t/logstash-filter-not-working/157984/2 "2018-11-23T10:42:11Z")

</div>

Try this instead:

```
if ([host] =~ /^192\.168\.0\.1/)

```

Obviously replace the IP address with your own.

---

<div class="post-metadata">

**Author:** ![DanielE](https://avatars.discourse-cdn.com/v4/letter/d/dfb087/32.png) [@DanielE](https://discuss.elastic.co/u/DanielE)\
**Post date:** [November 23, 2018, 2:09pm UTC](https://discuss.elastic.co/t/logstash-filter-not-working/157984/3 "2018-11-23T14:09:44Z")

</div>

Thank you! Worked like a charm!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 21, 2018, 2:11pm UTC](https://discuss.elastic.co/t/logstash-filter-not-working/157984/4 "2018-12-21T14:11:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
